25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Global Data Breach Cost Rises 12% to Almost $5 Million

The IBM 2026 Cost of a Data Breach Study shows data breach costs have risen by 12% in a year to almost $5 million, with the United States facing the highest breach costs. In 2026, the average cost of a data breach in the United States was $11.5 million – more than double the average global data breach cost. Healthcare continues to face the highest breach costs, with an average cost of $6.64 million per incident, although healthcare data breach costs have fallen by 10.5% year-over-year from a global average of $7.42 million in 2025. Data breach costs increased in all sectors represented in the study, with the rise largely driven by increases in detection, escalation, and lost business costs.

In healthcare, 59% of breaches were malicious or criminal attacks, 26% were due to IT failures, and 13% were due to human error. Across all sectors, phishing (voice and SMS phishing) accounted for 17% of breaches and was the most common initial access vector and had an average breach cost of $5.9 million. The next most common vectors were supply chain compromise, abuse of valid accounts, drive-by compromise attacks, and social engineering.

For the first time in five years, the average time to identify and contain a breach increased, rising 2.5% from 2025. The attack vectors that proved most difficult to identify and contain were removable media and supply chain compromises, as they do not show up in malware scans or inbound traffic. Breaches involving either of these attack vectors took an average of 258 days to identify and resolve, compared to an average of 247 days across all attack types.

Attackers have embraced AI tools in all areas of their attacks, including scanning for vulnerabilities, crafting phishing and social engineering lures, and automating attacks at scale. There has been a 56% year-over-year increase in AI-driven attacks, with one in four organizations having experienced an AI-driven breach in the past year.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

AI deepfake and impersonation accounted for 45% of AI-driven attacks, with AI-generated malware becoming more common, accounting for 19% of AI-generated attacks. AI-generated phishing or other communications accounted for 17% of attacks. AI-driven attacks have an increased financial impact, adding around $1 million to average data breach costs. Most AI-driven attacks targeted critical infrastructure, with the financial services and energy sectors the most targeted.

There has also been an increase in shadow AI incidents – AI applications used by employees that have not been approved for use. Incidents more than doubled to 43% of security incidents this year from 20% last year. IBM notes a lack of governance policies to mitigate or manage the risk to AI, with only around one third of organizations having a strict approval for deploying AI tools. The average breach cost was $5.39 million, and one in five of these breaches resulted in a regulatory fine.

There is growing concern about new threats from frontier AI models. Out of all breached organizations, 85% of organizations that were aware of frontier models said they were increasing their security spending to combat the threat. IBM notes that experts believe that AI will favor attackers over defenders by 31.7% within two years, highlighting the pressing need for speed in security.

While organizations are adopting AI for security, most are only using AI agents for detection and containment. Only a small fraction use AI agents for vulnerability management. That means exposures are available for exploitation for much longer, and given that attackers are using AI tools for vulnerability discovery, this is one of the key areas where organizations can make significant security gains. IBM recommends leveraging AI to analyze exposures, enforce policies, and coordinate detection and containment with minimal human intervention.

Ransomware attacks have continued to increase due to ransomware-as-a-service. Over the past 12 months, 39% of breached organizations said they experienced at least one ransomware attack, up from 24% in 2023 – a 62.5% increase over the past four years.  Attackers are increasingly threatening public shaming and data leaks to pressure victims into paying, rather than simply encrypting files. In 2026, 41% of ransomware attacks included brand reputation threats, such as data leaks and public shaming, with 35% of attacks targeting employee data and health records.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist